by alt_comp_virus on October 3rd, 2003

alt_comp_virus

Question

Help answer this question below.

What is a false positive?

  • Like
  • Report

Answers. 7 helpful answers below.

  • by alt_comp_virus on October 3rd, 2003

    alt_comp_virus

    When an antivirus program incorrectly reports a virus in memory or infecting a file or system area. Heuristic scanners & integrity checkers are, by definition, somewhat more prone to these. Also known as false alarms, though this may have a wider application.

    • Like
    • Report

    No comments. Post one | Permalink

  • by Master Selwood on July 22nd, 2009

    Master Selwood

    A false positive is something marked as harmful, when infact it is perfectly ok. Take Anti-Virus softwares, they all have false positives, its just some like Avg, Avast etc that pick up something, that there not even supposed to pick up, like a false alert.

    No comments. Post one | Permalink

  • by Zenless on July 7th, 2009

    Zenless

    In medicine testing, it's a misleading result. Happens all the time. You get tested for tuberculosis (PPD) and you get a skin reaction, but you don't have tuberculosis you have sensitive skin: False positive.

    No comments. Post one | Permalink

  • by citaj.com on July 7th, 2009

    citaj.com

    It must be something negative :).

    No comments. Post one | Permalink

  • by james123 on July 7th, 2009

    james123

    A False Positive is when you think you have a specific vulnerability in your program but in fact you don't. Many security scanners such as Nessus scan an application (or service/daemon) and attempt to find a vulnerability in it. Sometimes the signatures (the 'check logic') make mistakes and report a vulnerability that may not exist. False positive are not limited to scanners they also affect 'Web Application Firewalls' and 'NIDS's/IDS's/IPS's'. These monitoring products may report an attack attempt but sometimes confuse the data it received with valid information. Every once in awhile you may run a scanner that reports you as being vulnerable to a specific product (Like websphere) that you don't actually run. Sometimes the same vulnerability exists in multiple products but when the 'check' was written it was written with a specific application in mind and therefore the product and/or description for the vulnerability may not be 100% accurate.

    Unfortunately false positives will continute to exist but they can be limited by the skill of the person writing the signatures or check logic. Before you go complaining to the vendor/author of the product you're using saying 'you need to learn how to write checks better' remember that these checks are carefully written and tested and you cannot always predict what everyone's custom environment will look like. If you think you have a false positive carefully work with the author/vendor to try and address the solution. Who knows maybe you *are in fact vulnerable*, or something else is vulnerable to that particular 'security check' as outlined above.

    No comments. Post one | Permalink

  • by Mohamed El-Galley on July 7th, 2009

    Mohamed El-Galley

    A False positive is a false alarm made by either a anti-virus/spyware or a firewall. Be careful when checking a false positive because it might not be false. Go to virustotal.com to check anything suspicious by over 40 anti-virus/spyware scanners.

    No comments. Post one | Permalink

  • by R0Bb_AW3S0M3 on February 24th, 2010

    R0Bb_AW3S0M3

    A false Positive is when an Anti-Virus detects a program that is not a virus, but it thinks it is. I had Gamespy Arcade installed on my PC (but never used it) and McAfee detected it as Adware.

    No comments. Post one | Permalink

Want to attach an image to your answer? Click here.

Did this answer your question? If not, then ask a new question or create a poll.

More Questions. Additional questions in this category.

You're reading What is a false positive?

Follow us on Facebook!

Related Ads

ANSWERBAG BUZZ

What is a dbs
What is a false positive in computer world
Nessus false positive definition
What is a false positive tb